ZeroHour
Fortinet PSIRTpublished ()ingested

Stack buffer overflow in WAD

lowAdvisoryimportance 24
AI summary · glm-5.3-flash

FortiOS explicit proxy WAD daemon stack buffer overflow (CVSS 5.1) allows code execution only with Kerberos and SOCKS configured.

Fortinet advisory FG-IR-26-161 describes a stack-based buffer overflow (CWE-121) in the WAD daemon of FortiOS explicit proxy, scored CVSSv3 5.1. Exploitation requires an attacker able to bypass stack protection and ASLR, and the explicit proxy must be configured with Kerberos authentication and SOCKS enabled. If successful, it yields arbitrary code or command execution in the WAD daemon context via crafted sockets. No exploitation is reported in the advisory.

  • Stack buffer overflow (CWE-121) in the FortiOS WAD daemon
  • Requires Kerberos authentication and SOCKS on the explicit proxy
  • Exploit must bypass stack protection and ASLR; CVSSv3 5.1
VendorsFortinet
ProductsFortiOS
OrganizationsFortinet
Full article

CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.